![ZyXEL Communications USG110 Скачать руководство пользователя страница 174](http://html1.mh-extra.com/html/zyxel-communications/usg110/usg110_user-manual_943743174.webp)
Chapter 5 Quick Setup Wizards
ZyWALL USG Series User’s Guide
174
Figure 145
VPN for Configuration Provisioning Advanced Wizard: Phase 2 Settings
•
Active Protocol
:
ESP
is compatible with NAT.
AH
is not available in this wizard.
•
Encapsulation
:
Tunnel
is compatible with NAT,
Transport
is not.
•
Encryption Algorithm
:
3DES
and
AES
use encryption. The longer the
AES
key, the higher the security
(this may affect throughput).
Null
uses no encryption.
•
Authentication Algorithm
: MD5 (Message Digest 5) and SHA (Secure Hash Algorithm) are hash
algorithms used to authenticate packet data.
MD5
gives minimal security.
SHA1
gives higher security
and
SHA256
gives the highest security. The stronger the algorithm, the slower it is.
•
SA Life Time
: Set how often the Zyxel Device renegotiates the IKE SA. A short SA life time increases
security, but renegotiation temporarily disconnects the VPN tunnel.
•
Perfect Forward Secrecy (PFS):
Disabling PFS allows faster IPSec setup, but is less secure. Select DH1,
DH2 or DH5 to enable PFS.
DH5
is more secure than
DH1
or
DH2
(although it may affect throughput).
DH1 refers to Diffie-Hellman Group 1 a 768 bit random number. DH2 refers to Diffie-Hellman Group 2 a
1024 bit (1Kb) random number. DH5 refers to Diffie-Hellman Group 5 a 1536 bit random number (more
secure, yet slower).
•
Local Policy (IP/Mask)
: Type the IP address of a computer on your network. You can also specify a
subnet. This must match the remote IP address configured on the remote IPSec device.
•
Remote Policy (IP/Mask)
: A
ny
displays in this field because it is not configurable in this wizard.
•
Nailed-Up
: This displays for the site-to-site and remote access client role scenarios. Select this to have
the Zyxel Device automatically renegotiate the IPSec SA when the SA life time expires.
5.4.8 VPN Settings for Configuration Provisioning Advanced Wizard -
Summary
This is a read-only summary of the VPN tunnel settings.
Содержание USG110
Страница 27: ...27 PART I User s Guide ...
Страница 67: ...Chapter 2 Initial Setup Wizard ZyWALL USG Series User s Guide 67 Figure 41 Object Service Service Group HTTPS ...
Страница 195: ...195 PART II Technical Reference ...
Страница 282: ...Chapter 9 Wireless ZyWALL USG Series User s Guide 282 Figure 229 Configuration Wireless AP Management AP Group Add Edit ...
Страница 309: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 309 ...
Страница 310: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 310 Configuration Network Interface Ethernet Edit External Type ...
Страница 312: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 312 Configuration Network Interface Ethernet Edit Internal Type ...
Страница 313: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 313 ...
Страница 314: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 314 Figure 246 Configuration Network Interface Ethernet Edit OPT ...
Страница 315: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 315 Configuration Network Interface Ethernet Edit OPT ...
Страница 334: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 334 Figure 255 Configuration Network Interface PPP Add ...
Страница 342: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 342 Figure 257 Configuration Network Interface Cellular Add Edit ...
Страница 357: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 357 Figure 267 Configuration Network Interface VLAN Add Edit ...
Страница 358: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 358 ...
Страница 372: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 372 Figure 269 Configuration Network Interface Bridge Add Edit ...
Страница 373: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 373 ...
Страница 565: ...Chapter 25 Walled Garden ZyWALL USG Series User s Guide 565 Figure 399 Walled Garden Login Example ...
Страница 613: ...Chapter 30 IPSec VPN ZyWALL USG Series User s Guide 613 Figure 431 Configuration VPN IPSec VPN VPN Connection Add Edit ...
Страница 621: ...Chapter 30 IPSec VPN ZyWALL USG Series User s Guide 621 Figure 433 Configuration VPN IPSec VPN VPN Gateway Add Edit ...
Страница 651: ...Chapter 31 SSL VPN ZyWALL USG Series User s Guide 651 Figure 454 Create a Web Application SSL Application Object ...
Страница 664: ...Chapter 32 SSL User Screens ZyWALL USG Series User s Guide 664 4 Next run and log into the SecuExtender client ...
Страница 730: ...Chapter 38 IDP ZyWALL USG Series User s Guide 730 Figure 508 Configuration UTM Profile IDP Custom Signatures Add Edit ...
Страница 784: ...Chapter 42 Device HA ZyWALL USG Series User s Guide 784 Figure 541 Configuration Device HA Device HA ...
Страница 929: ...Chapter 44 System ZyWALL USG Series User s Guide 929 Figure 648 Configuration System WWW Login Page Desktop View ...
Страница 978: ...Chapter 45 Log and Report ZyWALL USG Series User s Guide 978 Figure 696 Log Category Settings AC ...
Страница 1011: ...Chapter 47 Diagnostics ZyWALL USG Series User s Guide 1011 Figure 720 Maintenance Diagnostics Network Tool ...